Surecart
by WordPress
Source repositories
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-9065 | Cri | 0.60 | — | 0.00 | May 20, 2026 | SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'provider') on the REST API endpoint '/surecart/v1/integrations/{id}'. The root cause is a flawed escaping bypass in the query… | ||
| CVE-2026-18480 | Hig | 0.57 | 8.8 | 0.00 | Sep 6, 2026 | The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's,… | ||
| CVE-2026-97245 | Hig | 0.47 | 7.2 | — | Sep 30, 2026 | Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions. | ||
| CVE-2024-43970 | Hig | 0.46 | 7.1 | 0.00 | Sep 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SureCart allows Reflected XSS.This issue affects SureCart: from n/a through 2.29.3. | ||
| CVE-2026-75793 | Med | 0.42 | 6.5 | 0.00 | Sep 6, 2026 | The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. | ||
| CVE-2026-39488 | Med | 0.42 | 6.5 | 0.00 | Apr 8, 2026 | Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SureCart: from n/a through <= 4.0.2. | ||
| CVE-2023-41241 | Med | 0.38 | 5.9 | 0.00 | Sep 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SureCart WordPress Ecommerce For Creating Fast Online Stores plugin <= 2.5.0 versions. | ||
| CVE-2026-32548 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. | ||
| CVE-2026-7655 | Hig | 0.00 | 8.1 | 0.00 | Jul 11, 2026 | The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile… | ||
| CVE-2026-57314 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions. | ||
| CVE-2026-57313 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions. |
- risk 0.60cvss —epss 0.00
SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'provider') on the REST API endpoint '/surecart/v1/integrations/{id}'. The root cause is a flawed escaping bypass in the query…
- risk 0.57cvss 8.8epss 0.00
The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's,…
- risk 0.47cvss 7.2epss —
Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SureCart allows Reflected XSS.This issue affects SureCart: from n/a through 2.29.3.
- risk 0.42cvss 6.5epss 0.00
The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.
- risk 0.42cvss 6.5epss 0.00
Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SureCart: from n/a through <= 4.0.2.
- risk 0.38cvss 5.9epss 0.00
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SureCart WordPress Ecommerce For Creating Fast Online Stores plugin <= 2.5.0 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
- risk 0.00cvss 8.1epss 0.00
The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile…
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.